Time to start looking into cyber security frameworks. For this episode we’re looking at the the NIST Cyber Security Framework. We’re also explaining what a cyber security framework is and how they can help.
LINKS
FIND US ON
Twitter - DamienHull
YouTube
Time for another maintenance episode where we review our systems and management process. This time were looking at our Digital Ocean servers, Automox patch management, Fortinet Firewalls, and the password manager Bitwarden.
FIND US ON
Twitter - DamienHull
YouTube
Almost roasted our VMware server to death. Don’t do what I did. Enjoy!
LINKS
VMware Server: Super Micro SYS-E300-9D-8CN8TP
Fans: Noctua NF-A4x20 PWM
FIND US ON
Twitter - DamienHull
YouTube
LastPass was hacked last year. As LastPass customers we need to evaluate the impact that has on Section 9. Should we continue to use the product? Should we migrate to a different password manager? How do we evaluate a password manager?
Consider this the start of a longer conversation about LastPass and password managers.
FIND US ON
Twitter - DamienHull
YouTube
Found some really interesting and helpful videos. One walks you through an Active Directory hacking lab. Another talks about default configurations and bad passwords as a way to hack into systems. The last one is about building a home lab.
These are just what I needed.
LINKS
SANS Workshop – NTLM Relaying 101: How Internal Pentesters Compromise Domains
The Top $ num Reasons You Got Hacked in 2022 with Kent & Jordan | 1 Hour
How to Build a Home Lab for Infosec with Ralph May | 1 Hour
FIND US ON
Twitter - DamienHull
YouTube
Found a video that walks you through the process of setting up an Active Directory Lab for hacking. I wouldn’t be able to do this without a starting point.
LINKS
Mitre ATT&CK Matrix
How to Build an Active Directory Hacking Lab
FIND US ON
Twitter - DamienHull
YouTube
Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.
FIND US ON
Twitter - DamienHull
YouTube
Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.
FIND US ON
Twitter - DamienHull
YouTube
Time to jump into my crazy, unorganized study process. Trying to study or learn the CISSP, pentesting, risk assessments, and keep up with my current certification requirements. I’ve also signed up for two Antisyphon classes.
Beginner Classes
SOC Core Skills
Getting Started In Security With BHIS and Mitre Att&ck
Active Defense & Cyber Deception
Advanced Classes
Introduction to Pentesting
Red Team: Getting Access
Professionally Evil CISSP Mentorship Program
FIND US ON
Twitter - DamienHull
YouTube
Time to create a policy for asset inventory. This will help us define what we need in our asset inventory. It will also help us define what we need in our procedures. The process we use to manage the inventory.
LINKS
FIND US ON
Twitter - DamienHull
YouTube
We’re scanning our network with runZero to get an inventory of devices. What did it find? What can we learn from this inventory? How well does it work?
LINKS
FIND US ON
Twitter - DamienHull
YouTube
We’re in the process of implementing the CIS controls. This will take time. We’re also very busy. Are there any gaping security holes that we need to fix? Do we have any security controls in place? Can we wait to implement the CIS controls?
LINKS
runZero - Active discovery tool for asset inventory
Enterprise Asset Management Policy Template
FIND US ON
Twitter - DamienHull
YouTube
Time to get an accurate inventory of the devices on our network. Once we have an inventory, we can move on to policies and procedures.
LINKS
runZero - Active discovery tool for asset inventory
Enterprise Asset Management Policy Template
FIND US ON
Twitter - DamienHull
YouTube
Time for another maintenance episode. This time were going back to the CIS Controls. This time were using version 8. Hoping to implement the first 7.
FIND US ON
Twitter - DamienHull
YouTube
Time to start learning Azure. We’ve had Azure AD and Microsoft 365 for years. Just added Azure to the mix. Lots to learn.
LINKS
Free Azure Account
FIND US ON
Twitter - DamienHull
YouTube
Time to go down the OSINT rabbit hole. What is it? What are we looking for? What are some of the tools we can use?
LINKS
Kali Linux
Shodan
Spiderfoot
theHarvester
OSINT Framework
FIND US ON
Twitter - DamienHull
YouTube
Time to dig in and start learning the tools.
LINKS
Kali Linux
Nmap
Shodan
Gophish
Zap
Burp Suite
FIND US ON
Twitter - DamienHull
YouTube
Got a new job. This makes our lab environment more important than ever. Some labs will be for me. Others will be for work. We need to make sure everything is working. We also need good documentation. No more messing around.
FIND US ON
Twitter - DamienHull
YouTube
There could be a new job in my future. Before that happens, we need to organize our IT. We’re looking at patching, Microsoft Defender for Business, and data recovery.
FIND US ON
Twitter - DamienHull
YouTube
Time for some new projects. Still have a few things to do with Wazuh. Once that’s done, I’ll need something new to work on. Python is the big one. Seems everyone is asking for Python skills these days.
LINKS
FIND US ON
Twitter - DamienHull
YouTube
Wazuh! It works! Not only does it work, but it’s awesome. We’re also covering detection as part of a security program. You can’t have good security without detection. We’re also throwing in a bit of VMware management. Can’t manage labs in VMware without some management know how.
LINKS
Wazuh · The Open Source Security Platform
Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh
Sysmon config from SwiftOnSecurity
Wazuh Server Rules
Video: Installing The EDR Solution Wazuh
FIND US ON
Twitter - DamienHull
YouTube
Time for more Wazuh and Sysmon. This time we’re adding Atomic Red Team for testing. This is starting to look really good. Unfortunately we’re missing something.
LINKS
Wazuh · The Open Source Security Platform
Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh
Sysmon config from SwiftOnSecurity
Wazuh Server Rules
Video: 163. Use Sysinternals Sysmon with Wazuh: The Swiss Army Knife for Windows Monitoring
FIND US ON
Twitter - DamienHull
YouTube
We’ve packed a lot into one episode. We’re reviewing Dorothy’s lab, Wazuh & Sysmon and Microsoft 365. We do have some good news. Got Sysmon installed. We also have access to good Microsoft 365 instructions and a book. We’re moving in the right direction.
LINKS
Sysmon Installation
Microsoft 365 Business Premium Partner Playbook and Readiness Series
Office 365 for IT Pros
ITProMentor: The Microsoft 365 Consultant’s Bundle
FIND US ON
Twitter - DamienHull
YouTube
There are many ways to answer this question. First, you need some skills. For this ongoing project we’ve decided to focus on Windows. Server 2019, Windows 10 and 11, and a bit of networking for good measure. One has to start somewhere.
FIND US ON
Twitter - DamienHull
YouTube
We’re in the process of testing Microsoft Defender for Business. This includes vulnerability management, endpoint detection and response and a lot more. This could be the security solution we’ve been looking for.
LINKS
Overview of Microsoft Defender for Business
Video: Onboarding Windows 10 devices to Defender for Business
FIND US ON
Twitter - DamienHull
YouTube
Of course security solutions aren’t 100% perfect. So, why are people building security programs around perfect solutions?
LINKS
FIND US ON
Twitter - DamienHull
YouTube
Time to go deeper down the Sysmon rabbit hole. Looks like Wazuh does a lot more than we thought.
LINKS
Sysmon
Wazuh
FIND US ON
Twitter - DamienHull
YouTube
Time to start thinking about our Sysmon deployment. There are a lot of moving parts to this project. It won’t be a simple install on Windows 10. That’s just a small part of the project.
LINKS
Security Onion
Getting started with Elastic Stack
Sysmon
Wazuh
FIND US ON
Twitter - DamienHull
YouTube
We’re conducting a mini security audit. We’ve got our short list of things we’re doing for security. Are they working for us? Are there things we need to change? How are we doing?
LINKS
Security Onion
Getting started with Elastic Stack
Sysmon
AppLocker
FIND US ON
Twitter - DamienHull
YouTube
It works! We have application allow listing with AppLocker. Pushed out the settings from Intune. This is awesome!
NOTE: No links to instructions for Intune and AppLocker. I need to find good documentation or write my own.
LINKS
Security Onion
Getting started with Elastic Stack
Sysmon
AppLocker
FIND US ON
Twitter - DamienHull
YouTube
We’ve come up with a short list of things we should do for security. These are industry recommended solutions. They make it extremely hard for an attacker to get in.
LINKS
Security Onion
Getting started with Elastic Stack
Sysmon
AppLocker
FIND US ON
Twitter - DamienHull
YouTube
Security in a lab is one thing. Security in the real world is something else. Time to start thinking of real world solutions.
LINKS
FIND US ON
Twitter - DamienHull
YouTube
Do you know what devices are on your network? Do you have an accurate inventory? Discover what’s really connected to your network with Rumble.run. This is an awesome network discovery tool.
LINKS
Rumble.run
Nmap - Nice but not as cool as Rumble
FIND US ON
Twitter - DamienHull
YouTube
Time for another round of security training. This time it’s John Strands Cyber Deception class. We’re also talking about job hunting Jason Blanchard style.
LINKS
Active Defense & Cyber Deception w/ John Strand - Starts 1-24-22
Jason Blanchard: Twitter Account
Jason Blanchard: Twitch Account
FIND US ON
Twitter - DamienHull
YouTube
A proper explanation of our Fortinet firewall licensing. Goals, tasks, and lessons learned.
LINKS
FortiGate 60F - We have two of these.
Overlay Controller VPN (OCVPN)
FIND US ON
Time to get licenses for our Fortinet firewalls. They expire next month. We’re also planning for next year.
LINKS
Free Python Class - Focused on network automation.
FortiGate 60F - We have two of these.
FIND US ON
We’re talking Python classes, Wi-Fi issues, security training and more. We’re also beginning to plan for next year. Yup, the new year is right around the corner.
LINKS
FIND US ON
What’s next for our lab? What should we focus on? What kinds of things can we add to it?
FIND US ON
It use to take us forever to build a lab. Lots of documentation, testing and planning has changed that. Big step in the right direction.
FIND US ON
We need to build a new network. One that includes a Firewall, Windows Domain Controller, Windows 10 and Windows 11 workstations. This will be our starting lab. One we can add to in the future.
FIND US ON
As the title says, we’re analyzing logs with Logwatch. Big step in the right direction. Started this back in episode 218. Couldn’t get email to work. It works! Not only does it work, but we can catch evil.
LINKS
Logwatch
Postfix
How To Install and Configure Postfix on Ubuntu 20.04
Rsyslog TLS configuration : Ubuntu simple step-by-step
FIND US ON
Found a new tool called Netbox. This tool was designed to document large data centers. We’re trying to use it to document our network. Lots of cool features and lots of moving parts to think about.
LINKS
What is NetBox - FREE Network Documentation System?
i HATE network documentation....but NetBox might help // ft. Jeremy Cioara
Installing Netbox in 10 Minutes or Less
FIND US ON
Time to analyze our cloud server logs. For that we’re going to use Logwatch. This will require the Postfix SMTP server for sending email. We also need the UFW firewall. Once again, lots of moving parts.
LINKS
Logwatch
Postfix
How To Install and Configure Postfix on Ubuntu 20.04
FIND US ON
We’re talking Windows 11 and VMware Updates. Did an Install of Windows 11 in our VMware environment. This required a virtual TPM. Moved on to VMware updates. This included updates to ESXi and VCSA. Lots of moving parts to these projects.
LINKS
Create a Virtual Machine with a Virtual Trusted Platform Module
Configuring and Managing vSphere Native Key Provider
FIND US ON
We’re trying to get the most out of 365. That includes learning how to use apps like Teams, Planner, OneNote and more. There’s a lot of moving parts to this. Installing, configuring, training, standards and more. We’re still at the beginning stages of this process. We have a long way to go.
FIND US ON
Time to plan for a new Wi-Fi Access Point. We’re replacing our old Asus Wi-Fi router with a Fortinet Access Point. What are the risks? How much downtime will there be? What’s our backout plan?
FIND US ON
Time to add another DNS server to the network. This could be considered a small project. It still has a lot of moving parts. What OS should we use? What hardware should we use? Can we manage another server?
FIND US ON
Dorothy want’s to speed up the installation of Windows Server 2019 in the lab. We’re looking into an automated install. We’re also looking at all the steps leading up to the install. How do we connect to our VMware server? How do we create a VM? How do we make everything faster?
FIND US ON
Yes we can! We’re using Intune, Azure AD and Automox to manage two laptops. The same process we use for two could be applied to 1,000. Settings, applications and updates can all be pushed out with a few mouse clicks.
FIND US ON
I’ve had 3 job interviews this year. Here’s what I’ve learned so far.
FIND US ON
We’re focusing on basic Microsoft 365 security. We’re also reviewing our Microsoft 365 Business Premium Licensing.
LINKS
m365maps.com
Basic Security Set Up for Microsoft 365
FIND US ON
Got a nice email from a listener who happens to be managing Microsoft 365. He made some interesting suggestions. This got me thinking about how we use 365. Ended up falling down the rabbit hole. We still have a lot to learn about Microsoft 365.
LINKS
CBT Nuggets
Connect Azure Active Directory (Azure AD) data to Azure Sentinel
FIND US ON
Time to review our IT management process. We have some work to do.
FIND US ON
The Cybersecurity & Infrastructure Security Agency has a mandate for the print spooler service vulnerability. This mandate includes step by step instructions for fixing the vulnerability. For people like us, this is awesome!
LINKS
us-cert.cisa.gov - Their website.
Emergency Directive 21-04
FIND US ON
PrintNightmare and the out of band patch forced us to change. We needed to evaluate the way we handle out of band patches. Fortunately for us, this wasn’t a big deal.
LINKS
CVE-2021-34527 - For those that want to dive a little deeper.
Sans Internet Storm Center Podcast - Episode that talks about PrintNightmare
FIND US ON
Time to look for a new job and brush up on my skills. Following Jason Blanchard’s tips on job hunting. I’m also trying to improve my SIEM skills. A skill that I’ve seen a few job postings.
LINKS
Jason Blanchard - Twitter
Jason Blanchard - Twitch
ELK - Free SIEM Solution
Install ELK on Ubuntu 20.04 Focal Fossa Linux - The instructions I followed to setup ELK
FIND US ON
A couple episodes ago, we got to interview John Strand of Black Hills Information Security. He gave us a lot of really good information. In our last episode, we talked about the technical half of the interview. In this episode, we’re looking at the training he recommended.
LINKS
Training Trail - Organized list of training from Johns training company Antisyphon Training
Antisyphon Training Courses - This is where Johns training lives
Hack The Box
Holiday Hack Challenge 2020 - No Answers
Past Holiday Hack Changes
Answers to the 2019 Holiday Hack Challenge
FIND US ON
Twitter - DamienHull
In our last episode, we interviewed John Strand of Black Hills Information Security. Now it’s time to analyze what he said. For this episode, we’re looking at the technical side of the interview. We’re saving the training portion for another episode.
LINKS
The Essential 8 from Australia
DeepBlueCLI
Sysmon
Elastic Stack - ELK
Security Onion
LogonTracer
sigma
JPCERT Tools
JPCERT: Tool Analysis Results Sheet
FIND US ON
Twitter - DamienHull
Yes, we got to Interview John Strand from Black Hills Information Security. He was kind enough to donate his time. We covered first steps to improving security, best practice, tools and training.
Links to some of thing things John mentioned.
LogonTracer
sigma
JPCERT Tools
JPCERT: Tool Analysis Results Sheet
FIND US ON
Twitter - DamienHull
We’re looking into version 8 of the Critical Security Controls.
LINKS
The 18 CIS Controls
SANS: CIS Controls v8
FIND US ON
Twitter - DamienHull
This is episode 200. We’ve come a long way in 200 episodes.
LINKS
Project Management for the Unofficial Project Manager
Shared Calendar - Teams, Sharepoint and Calendar
Planner - Teams, Sharepoint and Planner
FIND US ON
Twitter - DamienHull
We’ve been busy. We figured out how to push an emergency patch. Then version 8 of the CIS Critical Security Controls was released. Simplified and reorganized. We’re slowly working our way through the list. Lots to do.
LINKS
Automox - Our patch management tool
CIS Controls Version 8
FIND US ON
Twitter - DamienHull
I did a lot of work to get our VMware server environment configured. Turns out we’re running out of drive space.
LINKS
Our VMware Server - mitxpc.com
Grafana dashboard for monitoring vCenter
Storage requirements for vCenter
FIND US ON
Twitter - DamienHull
Our VMware server is back online with new NVME drives. This project was more work than we had planned for. Still, typical for an IT project. They never go the way you expect them to.
FIND US ON
Twitter - DamienHull
I wanted to “Release the hounds” with bloodhound. I managed to get it working. That’s about all I can say. It was way more work than I thought it would be.
LINKS
Attacking Active Directory - Bloodhound - This guy knows bloodhound
BadBlood - Generate random users and groups in AD
Kali Linux - Incase you need it
FIND US ON
Twitter - DamienHull
Our VMware server is offline. We’re missing a part we need to install the drives. While we track that down, we need something to do. Planning labs, learning Visio, and project management are on the todo list.
LINKS
FIND US ON
Twitter - DamienHull
Time to do a security test of Active Directory. Going to be using Bloodhound, Plumhound, mimikats and Ping Kastle. Never used them before. First time for everything.
LINKS
Bloodhound
Plumhound
Mimikatz
PingCastle
BadBlood
FIND US ON
Twitter - DamienHull
Running into some issues with our VMware ESXi server. The not so good news, we don’t have enough drive space. The good news, we can fix that. The really good news, we have way more CPU power than I thought.
LINKS
Our VMware Server: Supermicro SYS-E300-9D-8CN8TP
Alternative VMware Server: Supermicro AS-E301-9D-8CN4
SUPERMICRO DUAL NVME M.2 PCI-E 3.0
SUPERMICRO 1U PCIE X8 RISER CARD (RSC-RR1U-E8)
SUPERMICRO DUAL NVME M.2 PCI-3.0 - Amazon
Samsung (MZ-V7S1T0B/AM) 970 EVO Pluss SSD 1TB
FIND US ON
Twitter - DamienHull
We just put up a tools section on our website. It’s a list of tools we use and some we would like to use. Most are security tools. Things you wouldn’t see outside of security.
LINKS
FIND US ON
Twitter - DamienHull
Looks like we need to learn more about Windows Hello. Dorothy got locked out of her laptop. Couldn’t reset her Windows Hello pin.
LINKS
FIND US ON
Twitter - DamienHull
We’re using our project management process to migrate to new iPhones. It might seem like a simple process. It isn’t. Not when you have to migrate authentication apps for 2FA. If we’re not carful, we could lock our selves out of things.
LINKS
FIND US ON
Twitter - DamienHull
We’re working on a project management process. Turns out we’ve been doing it wrong. A good book and few simple steps is all we needed.
LINKS
FIND US ON
Twitter - DamienHull
Our patch process is in place. Time to do a quick weekly patch review. We’ve got this process down to a couple of minutes. That’s it. That’s how long it takes us to review our patch process.
FIND US ON
Twitter - DamienHull
Our endpoint management process is awesome. We can push settings to Windows 10 and we’ve got patching under control. A weekly email tells us how we’re doing. We can manage our systems while sipping coffee.
LINKS
Microsoft Endpoint Manager
Automox
FIND US ON
Twitter - DamienHull
It’s a new year with new goals. This year we’re focusing on IT management, Security and certifications. We’re also trying our best to finish our endpoint management project. We won’t be able to automate everything. Not yet anyway.
LINKS
Microsoft Endpoint Manager
Automox
FIND US ON
Twitter - DamienHull
No break for us this year. We’re diving strait into workstation and laptop management. We’re doing this with Microsoft Endpoint Manger and Automox.
LINKS
Microsoft Endpoint Manager
Automox
FIND US ON
Twitter - DamienHull
You wake up, the servers down and there’s no DR plan. Good times! Nothing teaches you more then a disaster you weren’t prepared for. On the bright side, there’s SOC training to prep for.
FIND US ON
Twitter - DamienHull
How can Microsoft 365 business premium help us? How can it make our lives easier? Are their features we should be using? We migrated to 365. We got the basics working. Now it’s time to dig a little deeper.
FIND US ON
Twitter - DamienHull
The end of the year is right around the corner. Time to start thinking about next year. We’re also adding another tool to our toolkit.
FIND US ON
Twitter - DamienHull
Learning some interesting things about ITIL and Microsoft 365 conditional access. ITIL will help us organize Section 9. 365 conditional access will help us lock down Azure AD. This should make it harder for the hackers to get in.
LINKS
ITIL - Wikipedia Article for those who don’t know what this is
What is Conditional Access?
Manage emergency access accounts in Azure AD
FIND US ON
Twitter - DamienHull
This week we’re working on DR plans and Password Polices. The DR plan is for our DNS servers. We can’t afford to lose them. The password policy is about reducing risk with longer passwords. We’ve also got another tool for the toolbox.
LINKS
psftp
SANS Polices
SANS Password Policy - Link to the PDF
Wireshark
FIND US ON
Twitter - DamienHull
We don’t know much about 365 conditional access polices, but they look awesome. We’re also adding tools to the toolbox and deploying new devices. No rest for the crazy.
LINKS
What is Conditional Access?
What are security defaults?
Nmap
FIND US ON
Twitter - DamienHull
Our Microsoft 365 has failed logins from Russia. What do we do? Time for a risk assessment. We’re going to make our 365 more secure.
Microsoft 365
Error Codes - Lookup the error codes
Security Defaults
DeepBlueCLI
DeepBlueCLI - The GitHub site
Webcast: Attack Tactics 7 – The Logs You Are Looking For - Covers DeepBlueCLI
Log Analysis Part 2 – Detecting Host Attacks: Or, How I Found and Fell in Love with DeepBlueCLI - Good article
Sysmon
FIND US ON
Twitter - DamienHull
We’re talking about weekly tasks, 365 authentication issues, and training. On the training front we have ITIL 4, SOC and Windows 10.
LINKS
The SOC Age Or, A Young SOC Analyst's Illustrated Primer - Presentation from BHIS
SOC Core Skills w/ John Strand
ITIL 4 Foundation Course
FIND US ON
Twitter - DamienHull
This week we connected Jitibt to 365, found hidden licensing and learned how to be a SOC analyst. You can now contact us by sending email to support@section9.us.
LINKS
Black Hills Information Security Youtube Channel
CIS Benchmarks
Jitbit
FIND US ON
Twitter - DamienHull
We’re learning how to manage emergency accounts and data retention in 365. The good news, Microsoft has some pretty cool tools for data retention. The bad news, retention policies are a bit confusing.
LINKS
MJFChat: How to Handle Office 365 Backups
Microsoft 365 Retention Policies
Manage emergency access accounts in Azure AD
FIND US ON
Twitter - DamienHull
We’re slowly creating our test environment for Microsoft 365. We’re also looking at ways we can backup 365. Slow and steady wins the race. We’re two people learning to be 365 admins. Breaking something could equal a lot of downtime. We can’t afford downtime.
LINKS
MJFChat: How to Handle Office 365 Backups
Microsoft 365 Retention Policies
FIND US ON
Twitter - DamienHull
We did it! We migrated to 365. There were a few bumps along the way. Nothing major. We’re doing a quick review of the process and next steps. We have to learn how to be 365 admins.
FIND US ON
Twitter - DamienHull
Time to prep for a long winter with Covid-19. We want a nice environment for IT projects and studying. We still need to finish our Windows 10 cert. We’ve got other Microsoft 365 certs to look at. I’m finally going to get the ITIL cert. Lots to do this winter.
LINKS
Microsoft Learn
ITIL Training - This is the one I’m looking at. I’m sure there are others.
FIND US ON
Twitter - DamienHull
Yup, another 365 migration review. Overall we’re doing pretty good. We still need to make sure we’re moving in the right direction. Are we achieving our goals? What are our goals? How are we doing? How do we feel about the project?
LINKS
Microsoft 365: Getting started - Even at this stage this is still relevant
Plan your setup of Microsoft 365 for business - We’re close to running the setup wizard
Microsoft 365 identity models and Azure Active Directory - Windows 10 Authentication
FIND US ON
Twitter - DamienHull
We’re starting over again. Yup! Two steps forward, one step back. This time it’s not so bad. We found more documentation on Microsoft 365. Based on this, we’ve decided to review the signup process. The only way to do that is to start over.
LINKS
FIND US ON
Twitter - DamienHull
As the title says, we got it wrong. It happens. Unfortunately this is not a topic you want to get wrong.
LINKS
SANS Webcast: Why as a DoD Contractor Do I need to Be CMMC Compliant
Certified Professionals and Assessors
FIND US ON
Twitter - DamienHull
We’re moving forward with our Microsoft 365 migration. Signed up for an account using the 365 Business Premium license. Setup admin accounts for our selves. Getting ready to setup test accounts with Business Premium Licenses.
LINKS
Plan your setup of Microsoft 365 for business - We used this document
Get started - More documentation on Microsoft 365
FIND US ON
Twitter - DamienHull
You can’t have a good security program without Polices and Procedures. We’re not the best at writing Polices. Truth is, we’re like most people. Where do I start? How do I write a policy?
Lucky for us, there are resources out there to help us get started. This is a big step in the right direction for us. However, we’re just scratching the surface. We have a long way to go.
SANS Polices
Security Policy Templates - All of the SANS policies
Software Installation Policy - We will be using this
Password Protection Policy - We will be using this
Pandemic Response Planning Policy - Never thought we would need this
Security Resources
Small Business Cybersecurity Corner
Cybersecurity Resources Road Map
SANS CIS Critical Security Controls: Guidelines
FIND US ON
Twitter - DamienHull
Another episode on migrating to Microsoft 365. Most organizations are using it. It’s almost a standard in the business world. Should we be using Microsoft 365? Can we?
FIND US ON
Twitter - DamienHull
Time to start thinking about our Critical Security Controls audit. This will include policies and procedures. We can’t avoid good documentation.
FIND US ON
Twitter - DamienHull
Lots to talk about in this episode. We’re using pfSense firewalls in our virtual lab environment. We’ve been documenting things on slab.com. And we’ve been evaluating cloud security.
Links
pfSense
slab.com
CMMC - Cybersecurity Maturity Model Certification
FIND US ON
Twitter - DamienHull
Time to review the security of notion.so. They are responsible for protecting our data. We are responsible for putting it there. We need to make sure their security meats our requirements. If they don’t, we’ll have to look for a different solution.
LINKS
notion.so
notion security - an overview of their security
9 Common Questions About SOC 2 Compliance
Small Business Information Security: The Fundamentals
FIND US ON
Twitter - DamienHull
We’re taking a step back and focusing on documentation. We spend a lot of time looking things up. Time that could have been spent learning new things. Better documentation means less time spent looking things up. To help fix this problem, we’re looking into notion.so.
Notion.so is a web application designed for things like documentation. We’re still in the testing phase. So far, things are looking good. We have a long way to go.
LINKS
notion.so
notion security - an overview of their security
FIND US ON
Twitter - DamienHull
We signed up for the Purple Teaming class put on by Black Hills Information Security. It was a bit overwhelming, but we learned a lot.
LINKS
Class Git Hub Repository
Sysmon
The Hunting ELK
BadBlood
FIND US ON
Twitter - DamienHull
We’re doing a quick review of the Verizon Data Breach report. We’ere also looking at Micosoft 365 options. We’d like to migrate to it if we can.
LINKS
Verizon Data Breach Report
Microsoft 365 for business
FIND US ON
Twitter - DamienHull
Black Hills has put out another amazing blog post. This one is titled “A Pentester’s Voyage - The First Few Hours”. We’re not pentesters, but we can learn a lot from the process.
LINKS
FIND US ON
Twitter - DamienHull
We need to make sure our projects are useful. To help us do that, were mapping our projects to the Critical Security Controls. We’re also looking at the Black Hills presentation on How to Build a Home Lab. This is full of good information.
LINKS
Security Onion
Black Hills - How to Build a Home Lab
The Critical Security Controls
Atomic Red Team
Scythe
FIND US ON
Twitter - DamienHull
Its been an interesting week. Wireshark saved me at work. Wasn’t expecting that. I’ve been using the Security Onion training. Learning how to set it up and install test data. I’ve also realized that a security lab needs evil. How do you look for evil if you don’t have any?
LINKS
Security Onion
Windows logging Cheat Sheets
Black Hills - How to Build a Home Lab
FIND US ON
Twitter - DamienHull
Good news. Everything works! We still have to manage IP address, subnets, vlans, firewall rules and more. That hasn’t changed. What has changed is that it all works. Our hard work is paying off.
LINKS
This website includes the WindowsLogging Cheat Sheet, the Windows Advanced Logging Cheat Sheet and the Windows Sysmon Logging Cheat Sheet.
Sysmon
Sysmon Config
Webcast: Think You’re Compromised? What Do We Do Next?
Black Hills Information Security webcast. This is where I got most of my info.
FIND US ON
Twitter - DamienHull
That’s right, we have a new VMware server. We also have a new set of problems. How do we manage VMware? How do we access it over a vpn connection? What Fortinet firewall rules do we need? What IP address do we need? What subnets do we need?
We would love to start our Windows and security projects. That’s not going to happen until we get everything under control. Time for more documentation and process creation.
OUR VMWARE SERVER
VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP
Processor: 8 core Xeon
RAM: 128GB
M.2 SSD: 250GB
2.5” SSD: 500GB
VMWARE VIDEOS - We using version 7. The process is the same.
Installing Vmware ESXi 6.7 Tutorial
How to install VMware vSphere Hypervisor | ESXi 6.7 Free Install
FIND US ON
Twitter - DamienHull
Time to document our Fortinet equipment and plan for our VMware server. Dorothy will do the documentation. She needs to see how the network was put together. Once some of that’s done, we can pick out a server. The sooner we get the server the better.
LINKS - We’re panning to get one of these servers
VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP
VMWARE CERTFIED - SuperMicro SYS-E200-8D
FIND US ON
Twitter - DamienHull
Meraki firewall is out, Fortinet equipment is in. It works!
Things to think about:
How many devices do you have?
How many Subnets will you need?
How many switch ports do you need?
What kind of features do you need?
What kind of security do you want?
What’s high priority?
FIND US ON
Twitter - DamienHull
We have a VMware server. It’s kinda wimpy with only 32GB of RAM. We need more power. More power means we can do more things. We’re looking at hardware options.
LINKS - Hardware Options
VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP
VMWARE CERTFIED - SuperMicro SYS-E200-8D
More Virtualization Solutions from mitxpc.com
Server Monkey - Refurbished Servers
FIND US ON
Twitter - DamienHull
We installed Dorothy’s FortiGate Firewall. It works! Not only that, but we can see network traffic. What online apps are we using? What websites do we go to? Once we have this information we can plan for better security.
Note: We’ve given up on FortiClud Manager and FortiAnalyzer Cloud. For now.
FIND US ON
Twitter - DamienHull
It Works! Well, sort of. Our stack of Fortinet equipment is working. Unfortunately we’re not sure why. We just know it works. Another bit of good news is that we managed to do all the configuration from FortiManager Cloud. This is a big step in the right direction. We might make our April deadline after all.
We still have a long way to go.
FIND US ON
Twitter - DamienHull
Another Saturday, another issue with our Fortinet project. We’re not sure what happened. We had plans to configure the switch and the wireless access point. It wasn’t meant to be.
The firewall lost its connection to FortiManager Cloud. We had to call support for this one. Then our switch configuration wouldn’t work. Couldn’t push the change from FortiManager Cloud to the device.
Again, two steps forward, one step back.
FIND US ON
Twitter - DamienHull
Can we do a basic Fortinet firewall configuration? Yes we can. The trick is to start simple and work your way up to fancy. We still have no idea how to use the FortiManager Cloud configuration tool. We don’t know what to do with hardware switch interfaces. We’re not sure why vlan’s weren’t recommended. This is a two steps forward, one step back kind of episode.
At least we can create a basic configuration on the local device. That’s a big step in the right direction.
FIND US ON
Twitter - DamienHull
Time to get things connected to the cloud. FortiManager is Fortinets enterprise management solution. They have two versions. On prem and cloud. We went with the cloud version. Getting things connected was a bit tricky. Lucky for us Fortinet tech support is awesome.
LINKS
FortiManager
FortiManager Cloud
SSL VPN Vulnerability
FIND US ON
Twitter - DamienHull
We’re unboxing and connecting our Fortinet gear. There’s a lot to do before we start configuring our new Firewalls. Once again, we chose to go with the FortiGate 60F. This is the device we’re starting with. We will be going over each devices as we get to them.
FIND US ON
Twitter - DamienHull
Our FortiNet gear is on the way. It’s time to start thinking about our network design. What kind of traffic do we want going in and out of our network? Where do we place our servers? Do we need new IP space? Lots to think about before we deploy anything.
FIND US ON
Twitter - DamienHull
After carefully examining our options, I ordered our Fortinet equipment. How did we choose this hardware? What factors go into selecting a firewall? This is an expensive perches. Make sure you do your home work before you buy anything.
LINKS - These are the devices we’re getting
FortiGate 60F Data Sheet - We’re getting 2 of them.
ForitSwitch 108E-FPOE - Link takes you to a list of 100 series switches.
FortiAP 223E - Link takes you to a list of Standard AP models.
Fortinet’s 360 Protection Bundle - We’re getting one year of 360 protection.
FIND US ON
Twitter - DamienHull
We’re moving forward with our Fortinet firewall project. We’ve picket out a firewall, switch and access point. There’s still a lot of work to do before we order anything. We’re working with the Cisco Network Life Cycle. This will help us organize the project. We don’t want to miss anything.
LINKS
FortiGate 60F Data Sheet - We’re leaning in this direction.
ForitSwitch 108E-FPOE - Link takes you to a list of 100 series switches.
FortiAP 223E - Link takes you to a list of Standard AP models.
Fortinet’s 360 Protection Bundle - We’re getting this.
FIND US ON
Twitter - DamienHull
We’re getting a new firewall! That’s one of several projects happening early next year. Also on the list is our Azure migration and our certifications. We’re applying our relaxed company culture to these projects. We don’t want any unnecessary pressure on us. A lot of companies are go go go, get it done yesterday. We’d like to take our time. To do that, we’re giving our selves a lot of time. Time to make sure we get these projects done right.
Did I mention we’re switching from Meraki to Fortinet?
LINKS
Fortinet.com
FortiGate 60F Data Sheet - We’re leaning in this direction.
FortiGate Product Matrix
avfirewalls.com - I haven’t talked to them yet, but the website looks good.
Fortinet’s 360 Protection Bundle - We’re getting this.
FIND US ON
Twitter - DamienHull
This episode is about PlexTrac, security audits and company culture. We had planned to do security audits for others as part of our business. How can we do a security audit if we can’t even produce a podcast properly? Some of our show’s have been published with the wrong information. Not a big deal, but it is a sign that we’re doing things wrong.
We need a company culture that includes things like procedures. A company culture that promotes best practice. We’re working on it.
LINKS
FIND US ON
Twitter - DamienHull
Time to start planning for the Windows 10 certification. The modern desktop administrator associate. Why do we want this cert? What’s on the test? How do you study for it? What are some good study materials? We cover all of that. This isn’t our first cert test.
LINKS
Microsoft 365 Certifiied: Modern Desktop Administrator Associate
Modern Desktop Administrator learning path - Seems to include some free training
Microsoft 365 - Modernize your enterprise deployment with Windows 10 and Office 365 ProPlus - Free training from Microsoft
Windows 10 Exam Ref MD-100 - Microsoft book on Amazon
CBT Nuggets: Reducing the Barrier to Learning - Info about monthly pricing
FIND US ON
Twitter - DamienHull
We did okay this year. Managed to take a few steps in the right direction. Automated patching with Automox was one of them. It’s now time to start planning for 2020. We have a few certs and projects we want to work on. Microsoft is pushing cloud. Looks like we’re moving in that direction.
One more thing. Azure Works!
LINKS
Azure Security Engineer Associate
Microsoft 365 Certified Fundamentals
Microsoft 365 Certified: Security Administrator Associate
CBTnuggets: What You Need to Know about the New Windows 10 Exams
FIND US ON
Twitter - DamienHull
We’re running away to Hawaii for a week. What do we do with our systems? Something to think about when you’re IT team is just two people. Just like everything else we do here at Section 9. We need to plan for this.
FIND US ON
Twitter - DamienHull
The Microsoft Azure tutorial we’ve been following is more work than we thought. Accessing the Windows server 2016 VM in Azure is tricky. They want this directly connected to the internet with RDP wide open. That might work for testing. That’s not going to cut it log term. We need to lock this down. Easier said than done.
LINKS
Create an Azure Bastion host
Manage virtual machine access using just-in-time
Tutorial: Create and configure an Azure Active Directory Domain Services instance - The tutorial we’ve been following.
FIND US ON
Twitter - DamienHull
Thanks to Jack, a listener of the show, we’re looking at Azure pricing. What are we paying for? We’re not sure. Microsoft says they’re being transparent with Azure pricing. I’m not sure sure about that.
LINKS
Azure Pricing Calculator
Azure Support Plans
Pay-As-You-Go
Intro to the Cisco Lifecycle Services Approach - PDF
FIND US ON
Twitter - DamienHull
More Azure! We’ve added a custom domain and configured a password rest option. We’ve also made Dorothy an owner of the Azure subscription. It took a bit of research to get this done. The tutorial is good, but it doesn’t cover everything. We still have a long way to go.
LINKS
What is Azure Active Directory Domain Services?
Tutorial: Create and configure an Azure Active Directory Domain Services instance - This is the tutorial we’re using
FIND US ON
Twitter - DamienHull
Time to learn about Azure. Last episode we talked about Azure Active Directory Federated Services. What we really want is Azure AD DS.
LINKS
What is Azure Active Directory Domain Services?
Tutorial: Create and configure an Azure Active Directory Domain Services instance - This is the tutorial we’re using
FIND US ON
Twitter - DamienHull
We’re looking into new technology like Azure AD FS. Before we can start new projects, we need to get the operational side of things in order. We’ve done a good job of clearly defining a patch management process. It’s time to work on change, incident and project management.
LINKS
Deploying AD FS
Azure AD Connect
What is ITIL Incident Management?
Change Management
FIND US ON
Twitter - DamienHull
Are fancy security solutions like Palo Alto firewalls, ExtraHop or LogRhythm going to keep you secure? By them selves, no. It doesn’t matter what the vendor says. There’s no such thing as a security solution that magically saves the day. A good solid security process and best practice is the key to any security program.
FIND US ON
Twitter - DamienHull
How do we do section 9 projects, keep systems running, and record a weekly podcast while having full time jobs? We need the right combination of tools and process.
LINKS
monday.com
lucidchart.com
jitbit.com
FIND US ON
Twitter - DamienHull